{"id":"CVE-2026-43621","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-43621","summary":"Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged…","details":"Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.","published":"2026-08-26T22:16:24.643","modified":"2026-08-26T22:16:24.643","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/SimpleMachines/SMF/commit/6f0dc61958aa86a4b436a222f6176812ed5bbb95","label":"SimpleMachines/SMF@6f0dc61"},"references":[{"type":"WEB","url":"https://github.com/SimpleMachines/SMF/commit/6f0dc61958aa86a4b436a222f6176812ed5bbb95"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/simple-machines-forum-authorization-confusion-via-profile-load"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T22:16:24.643"}}